Registry Privacy Statement
Total Page:16
File Type:pdf, Size:1020Kb
Registry Privacy Statement INTRODUCTION About Afilias provides reliable, secure management of Internet top-level domains. As the registry operator for top-level domains (TLDs), Afilias maintains the responsibility for the operation of each TLD, including maintaining a registry of the domain names within each TLD. In connection with generic top-level domains (gTLDs), Afilias serves as the registry operator for these gTLDs under contracts with the Internet Corporation for Assigned Names and Numbers (ICANN), a not-for-profit private sector organization that is charged with coordinating and ensuring the stable and secure operation of the Internet’s unique identifier systems (https://www.icann.org). In connection with country-code top-level domains (ccTLDs), Afilias has entered into separate legal arrangement with the ccTLD managers for the provision of these services. Afilias is made up of Afilias Limited and its subsidiaries: Afilias Technologies Limited, Monolith Registry, LLC, and other registry operators (the “Afilias Group”). This privacy notice is issued on behalf of the Afilias Group so when we mention “Afilias”, “we”, “us” or “our”, we are referring to the relevant company in the Afilias Group responsible for your data. General Afilias is committed to processing your personal data in a fair and lawful manner. This Privacy Statement aims to provide information about Afilias’ collection and processing of personal data. Scope This Privacy Statement relates to our domain name registry system only. It is intended to outline the information we collect, how it is stored, used, shared, and protected, and your choices regarding use, access, and correction of your information. It is important that you read this Privacy Statement together with any other privacy policy or fair processing notice we may provide on specific occasions when we are collecting or processing personal data. This privacy notice supplements other notices and is not intended to override them. "Personal Data" means information relating to an identified or identifiable natural person. "Data Subject" means the individual to whom any given Personal Data covered by this Privacy Statement refers. 11 December 2019 Page 1 of 13 WHAT INFORMATION WE COLLECT Introduction We must collect and process some information in order to operate our registry services or provide support for registrars. When you register a domain name, the registrar collects information in accordance with requirements under their ICANN accreditation contract, including your name, address, telephone number and other personal data. Data may be relating to you (the registrant) or other persons nominated by you. Additionally, registrar personnel must provide personal contact data during accreditation for TLDs and when communicating with registry customer support. Types Collected in the Previous Twelve Months All domain names registered in our system may be associated with the following information, and registrars may have additional or special policies or requirements: Registered Name Holder (or Registrant): the legal owner of the domain name. Other Contacts: the entity or person authorized by the registrant to interact with the registrar on behalf of the registrant. Sponsoring registrar: The registrar authorized by the registrant or reseller to register and manage the domain. Nameservers: the domain nameservers to which the domain must be delegated in the DNS in order to function. The following information may also be provided: DNS Security information: public information published in the DNS to support the secure operation of the domain. The Registrant and Other Contacts may include the following information: A Unique ID for the contact, assigned by the Registry (may be referenced as “ROID”) A Unique ID for the contact, assigned by the Registrar Contact Name Organisation* Postal address information Communication information (e.g. Phone, Fax, Email) 11 December 2019 Page 2 of 13 Afilias also collects and processes: Certain data elements relating to the traffic accessing its system, including Internet Protocol Addresses (IP Addresses) Customer Relationship Management (CRM) data from our registrars for our use in connection with our services DNS log data created in the course of providing our services To the extent that such data is capable of being used to identify (alone or in conjunction with other data, an individual), it is treated as Personal Data under this Privacy Statement. How Collected Much of what we collect is provided directly by you during the process of registering a domain name from an ICANN accredited registrar pursuant to a domain name purchase contract. Afilias receives domain name registrations, and the associated personal data provided upon registration of a domain name by registrants, from ICANN accredited registrars. The registrar provides this information to Afilias when the domain is registered. Registrars Like most other domain name registries, all domain names registered in the Afilias system are registered via accredited third parties called registrars. These registrars are retailers or resellers who register domain names on behalf of their customers, and typically provide additional services (such as web hosting, email, and TLS/SSL certificates). In connection with ICANN administered gTLDs, requirements are outlined in both the registry and registrar contracts with ICANN and the subsequent required agreements between registries and registrars. Because of these relationships outlined by contractual requirements ICANN, registries, and registrars are often considered joint controllers for information collected, stored, transferred, and processed in line with our Registry Agreements with ICANN. (https://www.icann.org/resources/pages/registries/registries-agreements-en) In connection with ccTLDs, requirements concerning the collection and processing of Personal Data are outlined in the respective contracts between registries, registrars, and registrants. Please note that each registrar has its own policies and procedures and you should review a registrar’s privacy policy and procedures prior to your purchase of a domain name. Registrars are responsible for collecting and transferring registration data, presenting each registrant with their privacy policies, that of their registry partners, and information on the mechanisms for access and correction of their data. 11 December 2019 Page 3 of 13 Registrars have broad powers to register, delete, and modify the domain names that are registered for their customers. Registrars can also amend the above information at any time during the lifetime of the domain registration. Other Afilias also stores the following information: The creation date of the domain, The expiry date of the domain, Status codes used to facilitate management of the domain lifecycle, An authorisation code used for transfers. Because we do not directly interact with registrants, we do not receive or store any of the following information: The IP address of the registrar’s customer, Any financial or payment information, Any passwords or other multi-factor authentication information used by the registrant to access the registrar’s services. Registry services are not intended for children, and we do not knowingly collect data relating to children. HOW WE USE INFORMATION Commitment Afilias will make all reasonable efforts to ensure that Personal Data is processed only in relation to the purposes set out below including to fulfill Afilias’ contracts with ICANN. We will make all reasonable efforts to ensure that personal information is not further processed in a way incompatible with the purpose for which it was collected or received. Registry We use this data to provide registry services, to enforce our policies and to prevent, detect, and respond to malicious behavior and/or misuse of our services. DNS We use the domain name, name servers, and DNS security information (if any) to publish DNS zone files to facilitate the functioning of the domains. This information can be queried through 11 December 2019 Page 4 of 13 our public DNS servers. In connection with gTLDs, third parties can also access copies of the zone files after signing an agreement, or via ICANN’s Centralized Zone Data Service (CZDS) (https://czds.icann.org/) In providing the DNS services, Afilias collects and processes DNS queries, which includes both source and destination IP Address information, time and date stamps, and other technical information. We use this information to provide connectivity and routing, to identify and mitigate malicious and fraudulent activity, and to enhance our services. Afilias makes use of traffic data for technical purposes to enhance security and stability in its operations. Registration Data Directory Service (RDDS) The RDDS is a standard service operated by all domain name registries as required by ICANN. We may use Personal Data when dealing with complaints of trademark or copyright infringement or mitigating malicious and fraudulent activity. Afilias uses Personal Data and other information collected in the course of providing registry services to: comply with contractual requirements, ICANN policy requirements, law and regulation; investigate and respond to complaints of malicious and fraudulent activity; and enforce registry policies related to, without limitation, Personal Data accuracy, the use of proxy and/or privacy registration services, limitations on registration, and prohibitions against the use of domain names for other activity that is contrary